REMARKS 



The Office Action dated July 2, 2008, has been received and carefully noted. The 
above amendments to the claims, and the following remarks, are submitted as a full and 
complete response thereto. 

Claims 1-4, 7-22, and 25-28 are currently pending in the application, of which 
claims 1, 11-13, and 18-19 are independent claims. Claims 1-2, 4, 7-9, 11-16, 18-22, and 
25-27 have been amended to more particularly point out and distinctly claim the 
invention. No new matter has been added. Claims 5-6 and 23-24 have been cancelled 
without prejudice or disclaimer. Claims 1-4, 7-22, and 25-28 are respectfully submitted 
for consideration in view of the following remarks. 

Claims 1-7, 9, 1 1-14, 18-25, and 27 were rejected under 35 U.S.C. 102(e) as being 
anticipated by U.S. Patent Application Publication No. 2003/0084300 of Koike 
("Koike"). Applicants respectfully submit that the claims recite subject matter that is 
neither disclosed nor suggested in Koike. 

Claim 1, upon which claims 2-4 and 7-10 depend, is directed to a method 
including receiving at a broker a usage policy for constraints related to data of a user in a 
communication system, wherein said usage policy defines at least one strictness level 
parameter value for at least one attribute in the usage policy. The method also includes 
receiving a request for data associated with the user from a service provider in the 
communication system to the broker, wherein the service provider possesses a privacy 
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policy and wherein said request comprises at least one strictness level parameter value for 
at least one attribute in the privacy policy. The method further includes checking, in the 
broker, the request against a usage policy of the user by comparing strictness level 
parameter values associated with attributes in the usage policy to corresponding strictness 
level parameter values associated with corresponding attributes in the privacy policy. 
The method additionally includes sending a response to the service provider indicating 
whether the data can be released, based on the comparison of the strictness level 
parameter values associated with attributes in the usage policy to corresponding strictness 
level parameter values associated with corresponding attributes the privacy policy. 

Claim 1 1 is directed to a system including a service provider possessing a privacy 
policy. The system also includes a broker hosting a usage policy for constraints related to 
data of a user, wherein said usage policy defines at least one strictness level parameter 
value for at least one attribute in the usage policy, wherein the broker is configured to 
check a request from the service provider against the usage policy of the user by 
comparing strictness level parameter values associated with attributes in the usage policy 
to corresponding strictness level parameter values associated with corresponding 
attributes in the privacy policy, wherein said request comprises at least one strictness 
level parameter value for at least one attribute in the privacy policy, and the broker is 
configured to send a response to the service provider indicating whether data associated 
with the user can be released in response to the request based on the comparison of the 
strictness level parameter values associated with attributes in the usage policy to 
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corresponding strictness level parameter values associated with corresponding attributes 
the privacy policy. 

Claim 12 is directed to a system including introducing means for introducing to a 
broker a usage policy for constraints related to data of a user, wherein said usage policy 
defines at least one strictness level parameter value for at least one attribute in the usage 
policy. The system also includes receiving means for receiving a request for data 
associated with the user from a service provider to the broker, wherein the service 
provider possesses a privacy policy and wherein said request comprises at least one 
strictness level parameter value for at least one attribute in the privacy policy. The 
system further includes checking means for checking, in the broker, the request against a 
usage policy of the user by comparing strictness level parameter values associated with 
attributes in the usage policy to corresponding strictness level parameter values 
associated with corresponding attributes in the privacy policy. The system additionally 
includes sending means for sending a response to the service provider indicating whether 
the data can be released, based on the comparison of the strictness level parameter values 
associated with attributes in the usage policy to corresponding strictness level parameter 
values associated with corresponding attributes the privacy policy. 

Claim 13, upon which claims 14-17 depend, is directed to an apparatus including a 
receiver configured to receive a request for data associated with a user from a service 
provider, wherein the service provider possesses a privacy policy and wherein said 
request comprises at least one strictness level parameter value for at least one attribute in 
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the privacy policy. The apparatus also includes a processor configured to check the 
request against a usage policy of the user by comparing strictness level parameter values 
associated with attributes in the usage policy to corresponding strictness level parameter 
values associated with corresponding attributes in the privacy policy, wherein said usage 
policy defines at least one strictness level parameter value for at least one attribute in the 
usage policy and to send a response to the service provider indicating whether the data 
can be released, based on the comparison of the strictness level parameter values 
associated with attributes in the usage policy to corresponding strictness level parameter 
values associated with corresponding attributes the privacy policy. 

Claim 18 is directed to an apparatus including receiving means for receiving a 
request for data associated with a user from a service provider, wherein the service 
provider possesses a privacy policy and wherein said request comprises at least one 
strictness level parameter value for at least one attribute in the privacy policy. The 
apparatus also includes checking means for checking the request against a usage policy of 
the user by comparing strictness level parameter values associated with attributes in the 
usage policy to corresponding strictness level parameter values associated with 
corresponding attributes in the privacy policy, wherein said usage policy defines at least 
one strictness level parameter value for at least one attribute in the usage policy. The 
apparatus further includes sending means for sending a response to the service provider 
indicating whether the data can be released, based on the comparison of the strictness 
level parameter values associated with attributes in the usage policy to corresponding 
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strictness level parameter values associated with corresponding attributes the privacy 
policy. 

Claim 19, upon which claims 20-22 and 25-28 depend, is directed to a computer- 
readable medium comprising computer-executable components. The components are 
configured to receive a usage policy for constraints related to data of a user in a 
communication system, wherein said usage policy defines at least one strictness level 
parameter value for at least one attribute in the usage policy. The components are also 
configured to receive a request for data associated with the user from a service provider 
in the communication system, wherein the service provider possesses a privacy policy 
and wherein said request comprises at least one strictness level parameter value for at 
least one attribute in the privacy policy. The components are further configured to check 
the request against a usage policy of the user by comparing strictness level parameter 
values associated with attributes in the usage policy to corresponding strictness level 
parameter values associated with corresponding attributes in the privacy policy. The 
components are additionally configured to send a response to the service provider 
indicating whether the data can be released, based on the comparison of the strictness 
level parameter values associated with attributes in the usage policy to corresponding 
strictness level parameter values associated with corresponding attributes the privacy 
policy. 

Applicants respectfully submit that Koike fails to disclose or suggest all of the 
elements of any of the presently pending claims. 
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Koike generally relates to a system for administrating data including privacy of a 
user in communication made between a server and the user's terminal device. The 
system of Koike includes a server, a terminal device owned by the user, and a privacy 
data administrator connected between the server and the terminal device. The privacy 
data administrator, in Koike, compares a privacy policy made by the server and privacy 
preference determined by the user to each other, and determines whether the privacy data 
administrator is allowed to provide data, including privacy of the user, to the server. 

Claim 1 recites, in part, "sending a response to the service provider indicating 
whether the data can be released, based on the comparison of the strictness level 
parameter values associated with attributes in the usage policy to corresponding strictness 
level parameter values associated with corresponding attributes the privacy policy." 
Applicants respectfully submit that Koike does not disclose or suggest at least these 
features of claim 1 . 

The Office Action's discussion of Koike does not address the issue of using 
strictness level parameter values for attributes in privacy and usage policies, as such. It is 
respectfully submitted that Koike does not contain such discussion. 

Even assuming that Koike disclosed providing a response to a service provider 
indicating whether data can be released (not admitted), there is no discussion in Koike of 
a "comparison of the strictness level parameter values associated with attributes in the 
usage policy to corresponding strictness level parameter values associated with 
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corresponding attributes the privacy policy." Thus, the features of claim 1 are clearly 
distinguishable over Koike. 

Furthermore, as noted in the present application at paragraphs [0009] and [0010], 
the features of using strictness level parameter values for attributes in privacy and usage 
policies can advantageously allow for an easy way to check the matching or non- 
matching between different policies. Thus, the features of claim 1 are not only novel, but 
non-obvious with respect to Koike. 

Although independent claims 11-13 and 18-19 each have their own respective 
scope, each recites at least some features similar to those discussed above with respect to 
claim 1 . It is, therefore, respectfully requested that, for similar reasons, the respective 
rejections of each of claims 1, 11-13, and 18-19 be withdrawn. 

Claims 2-4, 7, 9, 14, 20-22, 25, and 27 depend respectively from, and further limit 
claims 1, 13, and 19. Each of claims 2-4, 7, 9, 14, 20-22, 25, and 27, therefore, recites 
subject matter that is neither disclosed nor suggested in Koike. Claims 5-6 and 23-24 
have been cancelled without prejudice or disclaimer. It is, therefore, respectfully 
requested that the rejection of claims 2-7, 9, 14, 20-25, and 27 be withdrawn. 

Claims 1-8, 11-15, and 18-26 were rejected under 35 U.S.C. 102(e) as being 
anticipated by U.S. Patent Application Publication No. 2003/0088520 of Bohrer et al. 
("Bohrer"). Applicants respectfully submit that the claims recite subject matter that is 
neither disclosed nor suggested in Bohrer. 
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The independent claims are discussed above. Bohrer generally relates to a system, 
method, and business method for enforcing privacy preferences on personal-data 
exchanges across a network. In Bohrer, there are one or more data-subject rule sets that 
have one or more subject constraints on one or more private, subject data releases. A 
receiving process, in Bohrer, requires a request message from a data-requester over a 
network interface. The request message includes at least one request for one or more of 
the private, subject data releases pertaining to a subject, and a requester privacy statement 
for each of the respective private data. In Bohrer's system, a release process compares 
the requester privacy statement to the subject constraints and releases the private, subject 
data release in a response message to the requestor only when the subject constraints are 
satisfied. 

Claim 1 recites, in part, "sending a response to the service provider indicating 
whether the data can be released, based on the comparison of the strictness level 
parameter values associated with attributes in the usage policy to corresponding strictness 
level parameter values associated with corresponding attributes the privacy policy." 
Applicants respectfully submit that Bohrer does not disclose or suggest at least these 
features of claim 1 . 

The Office Action's discussion of Bohrer does not address the issue of using 
strictness level parameter values for attributes in privacy and usage policies, as such. It is 
respectfully submitted that Bohrer does not contain such discussion. 
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Even assuming that Bohrer disclosed providing a response to a service provider 
indicating whether data can be released (not admitted), there is no discussion in Bohrer of 
a "comparison of the strictness level parameter values associated with attributes in the 
usage policy to corresponding strictness level parameter values associated with 
corresponding attributes the privacy policy." Thus, the features of claim 1 are clearly 
distinguishable over Bohrer. 

Furthermore, as noted in the present application at paragraphs [0009] and [0010], 
the features of using strictness level parameter values for attributes in privacy and usage 
policies can advantageously allow for an easy way to check the matching or non- 
matching between different policies. Thus, the features of claim 1 are not only novel, but 
non-obvious with respect to Bohrer. 

Although independent claims 11-13 and 18-19 each have their own respective 
scope, each recites at least some features similar to those discussed above with respect to 
claim 1. It is, therefore, respectfully requested that, for similar reasons, the respective 
rejections of each of claims 1, 11-13, and 18-19 be withdrawn. 

Claims 2-4, 7-8, 14-15, 20-22, and 25-26 depend respectively from, and further 
limit claims 1, 13, and 19. Each of claims 2-4, 7-8, 14-15, 20-22, and 25-26, therefore, 
recites subject matter that is neither disclosed nor suggested in Bohrer. Claims 5-6 and 
23-24 have been cancelled without prejudice or disclaimer. It is, therefore, respectfully 
requested that the rejection of claims 2-8, 14-15, 20-22, and 25-26 be withdrawn. 
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Claims 9, 16, and 27 were rejected under 35 U.S.C. 103(a) as being unpatentable 
over Bohrer in view of Koike. Applicants respectfully submit that claims 9, 16, and 27 
recite subject matter that is neither disclosed nor suggested in the combination of Bohrer 
and Koike. 

Claims 9, 16, and 27 depend respectively from, and further limit, claims 1,13, and 
19. At least some of the deficiencies of Bohrer and Koike with respect to claims 1, 13, 
and 19. Because Bohrer and Koike share at least some of the deficiencies with respect to 
claims 1, 13, and 19 the combination of Bohrer and Koike likewise fails to disclose or 
suggest all of the elements of claims 1, 13, and 19 or of claims 9, 16, and 27, which 
depend therefrom. It is, therefore, respectfully requested that the rejection of claims 9, 
16, and 27 be withdrawn. 

Claims 10, 17, and 28 were rejected under 35 U.S.C. 103(a) as being unpatentable 
over Koike in view of U.S. Patent Application Publication No. 2005/0086061 of 
Holtmanns et al. ("Holtmanns"). The Office Action acknowledged that Koike fails to 
disclose at least some of the further limitations of the claims, and cited Holtmanns to 
remedy Koike's deficiencies. Applicants respectfully submit that the claims recite 
subject matter that is neither disclosed nor suggested in the combination of Koike and 
Holtmanns. 

Claims 10, 17, and 28 depend respectively from, and further limit, claims 1, 13, 
and 19. At least some of the deficiencies of Koike with respect to claims 1, 13, and 19 
are discussed above. Holtmanns fails to remedy the above-identified deficiencies of 
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Koike, and consequently the combination of Koike and Holtmanns fails to disclose or 
suggest all of the elements of any of the presently pending claims. 

Holtmanns generally relates to a method and apparatus for personal information 
access control Nevertheless, Holtmanns does not disclose or suggest, "sending a 
response to the service provider indicating whether the data can be released, based on the 
comparison of the strictness level parameter values associated with attributes in the usage 
policy to corresponding strictness level parameter values associated with corresponding 
attributes the privacy policy," as recited in claim 1 . Thus, Holtmanns does not remedy 
the above-identified deficiencies of Koike, and the combination of Koike and Holtmanns 
fails to disclose or suggest all of the elements of claims 1, 13, and 19. It is, therefore, 
respectfully requested that the rejection of claims 10, 17, and 28 be withdrawn. 

Claims 10, 17, and 28 were also rejected under 35 U.S.C. 103(a) as being 
unpatentable over Bohrer in view of Holtmanns. The Office Action acknowledged that 
Bohrer fails to disclose at least some of the further limitations of the claims, and cited 
Holtmanns to remedy Bohrer' s deficiencies. Applicants respectfully submit that the 
claims recite subject matter that is neither disclosed nor suggested in the combination of 
Bohrer and Holtmanns. 

Claims 10, 17, and 28 depend respectively from, and further limit, claims 1, 13, 
and 19. At least some of the deficiencies of Bohrer with respect to claims 1, 13, and 19 
are discussed above. Holtmanns fails to remedy the above-identified deficiencies of 
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Bohrer, and consequently the combination of Bohrer and Holtmanns fails to disclose or 
suggest all of the elements of any of the presently pending claims. 

Holtmanns generally relates to a method and apparatus for personal information 
access control. Nevertheless, Holtmanns does not disclose or suggest, "sending a 
response to the service provider indicating whether the data can be released, based on the 
comparison of the strictness level parameter values associated with attributes in the usage 
policy to corresponding strictness level parameter values associated with corresponding 
attributes the privacy policy," as recited in claim 1. Thus, Holtmanns does not remedy 
the above-identified deficiencies of Bohrer, and the combination of Bohrer and 
Holtmanns fails to disclose or suggest all of the elements of claims 1,13, and 19. It is, 
therefore, respectfully requested that the rejection of claims 10, 17, and 28 be withdrawn. 

For the reasons set forth above, it is respectfully submitted that each of claims 1-4, 
7-22, and 25-28 recites subject matter that is neither disclosed nor suggested in the cited 
art. It is, therefore, respectfully requested that all of claims 1-4, 7-22, and 25-28 be 
allowed, and that this application be passed to issuance. 

If for any reason the Examiner determines that the application is not now in 
condition for allowance, it is respectfully requested that the Examiner contact, by 
telephone, the Applicants 5 undersigned representative at the indicated telephone number 
to arrange for an interview to expedite the disposition of this application. 
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In the event this paper is not being timely filed, Applicants respectfully petition for 
an appropriate extension of time. Any fees for such an extension together with any 
additional fees may be charged to Counsel's Deposit Account 50-2222. 



Customer No. 32294 

SQUIRE, SANDERS & DEMPSEY L.L.P. 
14 th Floor 

8000 Towers Crescent Drive 
Vienna, Virginia 22182-6212 
Telephone: 703-720-7800 
Fax: 703-720-7802 

PCF:dlh:dk 

Enclosures: Petition for Extension of Time 
Check No. 20254 



Respectfully submitted, 




Peter Flanagan ( 
Attorney for Applicants 
Registration No. 58,178 
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